Skip to content

Data Segmentation Overview

Data segmentation provides global administrators the ability to create record-level security controls for their data. Data segmentation is a least-privileged way to scope non- Org Admin users’ access to data so you can delegate administration to identities beyond the Org Admin.

Previously, when a user was granted any given piece of Identity Security Cloud access in the UI, they were also granted access to any piece of information that UI can access. This means that there were specific objects like access model items, identities, etc. that should have limited visibility that were instead visible globally to anyone granted sub-administrator rights.

Organization administrators can now define segments that grant smaller chunks of admin access to different users, allowing you to spread out admin functionality to distributed teams. Data segmentation provides you with a policy driven, least privilege, data-level security control for administering entitlements, roles, and human identities. Data segmentation also makes it easier for sub-administrators to perform their work, because the only records available to them are those which they should have access to.

Note

When data segmentation is enabled for a tenant, any actions on Identity reports like run, view, or download can only be performed by Org Admins. Refer to Reporting Overview for more information.

Recipients of segment access can name, describe, create, manage configurations for, and maintain only those entitlements, roles, and identities that they are granted access to. Users assigned to a data segment may see that additional objects exist, due to the transitive property, but they will not have access to those objects’ details.

Note

Data segmentation is not supported in the Access Intelligence Center. It is also not supported in searching events.

Transitive Property in Data Segments

Due to the transitive property, users assigned to a data segment can sometimes see an object that they do not have explicit access to within their assigned data segment. This happens when your segment includes an access model object that references another object outside of your segment. You can see that the referenced object exists, however you will not be able to view any details about objects outside your segment if you do not have access to them.

For example, if role A is included in your segment, you can see the entitlements under it, including those that are not part of your segment. However, you will not be able to see details about those entitlements that are outside of the segment you are assigned to.

Using Data Segmentation

To use data segmentation, complete the following:

  1. Enable the data segmentation feature.
  2. Create data segments.
  3. Publish and enable your data segments.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.